PT-2026-69064 · Sonatype · Nexus Repository 3
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Nexus Repository 3 (affected versions not specified)
Description
Insufficient restrictions on HikariCP connection-pool properties within the DataStore configuration API allow a user with the
nx-datastores-update permission to set the connectionInitSql property. This enables the execution of arbitrary SQL against the configured database whenever a new connection is established. When using the default H2 database backend, this flaw can be exploited to achieve remote code execution with the privileges of the Nexus process user.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexus Repository 3